syncfusion-aspnetcore-tabs

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and downloads component assets from the official Syncfusion Content Delivery Network (CDN) for styling and functionality.
  • Evidence: References to https://cdn.syncfusion.com/ej2/{{ site.ej2version }}/fluent.css and https://cdn.syncfusion.com/ej2/{{ site.ej2version }}/dist/ej2.min.js in references/getting-started.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents methods for dynamically loading and rendering external HTML content, which represents a potential attack surface for indirect prompt injection if untrusted data is processed.
  • Ingestion points: Data ingested through the content property of TabItemModel and dynamically via fetch requests within event handlers like selected or contentLoad (documented in references/tab-content-rendering.md and references/advanced-features.md).
  • Boundary markers: The component uses standard web DOM isolation and manages state through browser-level constructs like localStorage.
  • Capability inventory: The examples demonstrate network access via the fetch API and the ability to modify the DOM directly using innerHTML.
  • Sanitization: The Tab component includes a built-in HTML sanitizer (enableHtmlSanitizer), which is enabled by default to strip potentially malicious code from content before rendering, as detailed in references/api-reference.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:08 PM
Security Audit — agent-trust-hub — syncfusion-aspnetcore-tabs